Section III
HIPCAR – Cybercrime/e-Crimes
(6) Computer Data
The drafters decided to base the definition of computer data on international standards. In order to
ensure that all types of content are covered the drafters provided examples in brackets.
(7) Computer Data Storage Medium
Not only the capacity but also the size and function of computer storage devices have changed within the
last decades. The drafters decided to formulate an open definition that covers mass storage devices as
well as micro storage systems that are for example used in car keys. This provision is therefore applicable
to both permanent as well as short-term storage devices (such as RAM).
(8) Critical Infrastructure
Today computer systems are not only used by private persons and businesses but also by the operators of
critical infrastructure, such as energy supply or traffic control. As infrastructure that is considered critical
varies from country to country the drafters decided to include a broad definition of critical infrastructure.
(9) Devices
The drafters decided to provide an open ended approach to the application of provisions referring to a
device by providing a set of examples. This list of examples is therefore not conclusive or limited but open
for new developments.
(10) Hinder
Some of the international approaches to address Cybercrime criminalize the illegal hindering of computer
systems without providing a precise definition of what is covered by the Act. The drafters decided to
ensure that the term hindering includes network based attacks (such as the transmission of computer
data) as well as physical attacks. Accidental cuts of power supply are covered by definition but are
excluded from criminal liability as the related provision (Sec. 9) requires the commission of the act as well
as intent.
(11) Hosting Provider
Similar to the definition of other categories of Internet service providers, the term hosting provider not
only includes a legal person but also a natural person. It is not necessary that the hosting provider
possesses storage devices. The operator of a website that allows users to post messages also acts as a
hosting provider.
(12) Hyperlink
The drafters decide to regulate the criminal responsibility of a hyperlink provider. In this context the law
provides a broad definition of hyperlink to cover the various different technical solutions.
(13) Interception
The interception of data transfer processes is a procedural instrument that can be found in different
international approaches to address Cybercrime. However, most of these instruments do not specify the
acts or provide details of the legitimate investigation procedures. The drafters decided to include some
examples for both legitimate acts as well as the types of communication that can be interception.
(14) Multiple Electronic Mail Messages
The drafters recognised the potential negative impact of SPAM for developing countries. One essential
component of a criminalisation of SPAM is the definition of multiple messages. In light of this the drafters
decided to require at least one thousand (1,000) messages.
> Model Policy Guidelines & Legislative Text
31